Skip to content

Option to toggle off CSRF token as url parameter #11190

@Asskali

Description

@Asskali

Expected Behavior

It should be possible to introduce a toggle that toggles the option of sending in the CSRF token as a URL parameter, and only allows for it as a header.

Current Behavior
When activating CSRF protection you have the option to send in the token as either a header or a URL parameter.

Context

Metadata

Metadata

Labels

in: webAn issue in web modules (web, webmvc)type: enhancementA general enhancement

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions